CVE-2018-15669

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/08/2018
Last modified:
04/05/2020

Description

An issue was discovered in Bloop Airmail 3 3.5.9 for macOS. Its primary WebView instance implements "webView:decidePolicyForNavigationAction:request:frame:decisionListener:" such that requests from HTMLIFrameElements are blacklisted. However, other sub-classes of HTMLFrameOwnerElements are not forbidden by the policy. An attacker may abuse HTML plug-in elements within an email to trigger frame navigation requests that bypass this filter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:bloop:airmail_3:3.5.9:*:*:*:*:macos:*:*


References to Advisories, Solutions, and Tools